{"podcast":{"title":"Threat Talks - Your Gateway to Cybersecurity Insights","slug":"threat-talks-your-gateway-to-cybersecurity-insights-6755159","podcast_index_feed_id":6755159,"rss_url":"https://feeds.transistor.fm/threat-talks-your-gateway-to-cybersecurity-insights","website_url":"https://threat-talks.com/","image_url":"https://img.transistorcdn.com/wqPeh6mA2wCORVwUDSv8RSIWcuUMzTZP0kjjqamexmc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xN2Q1/NGE1NjBhYWY0ZmY5/NzEyODA5OGU3NDdi/MmNmYi5qcGc.jpg","author":"Threat Talks","episode_count":126,"summary":"Threat Talks is your cybersecurity knowledge hub. Unpack the latest threats and explore industry trends with top experts as they break down the complexities of cyber threats. We make complex cybersecurity topics accessible and engaging for everyone, from IT professionals to every day internet users by providing in-depth and first-hand experiences from leading cybersecurity professionals. Join us for monthly deep dives into the dynamic world of cybersecurity, so you can stay informed, and stay secure!","last_synced_at":"2026-06-09T18:17:54.349616+00:00","page_url":"https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159"},"episode":{"title":"React2Shell Explained","slug":"react2shell-explained","published_at":"2026-03-24T08:59:00+00:00","page_url":"https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/react2shell-explained","show_page_url":"https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159","url":"https://threat-talks.com/react2shell-explained/","audio_url":"https://2.gum.fm/op3.dev/e/pdcn.co/e/pscrb.fm/rss/p/pdst.fm/e/dts.podtrac.com/redirect.mp3/media.transistor.fm/0c1bc2a6/f2bd1ae9.mp3","summary":"Log4j caught everyone off guard. React2Shell might be doing the same right now. Across thousands of React apps, exposure is already baked in - accelerated by vibe coding and shipped without scrutiny. In some cases, one request is all it takes. React2Shell turns that exposure into remote code execution in React and Next.js environments -triggered by a single HTTP POST request. In this episode of Threat Talks, host Rob Maas and SOC analyst Yuri Wit break down how React2Shell works, why it’s more serious than it looks, and what makes it so easy to exploit. The risk is significant, and what makes it worse is how little attention it’s getting. As developers increasingly rely on AI-generated code, applications are being shipped faster - but not always with full visibility into how components behave. That creates blind spots attackers can take advantage of, especially when serialization and deserialization flaws are involved. We cover how React2Shell works, how attackers exploit serialization and deserialization flaws, and what actions you need to take now to reduce risk. If your organization runs React or Next.js applications, assume exposure until proven otherwise - especially if this hasn’t been on your radar yet. React2Shell isn’t making Log4j headlines. That doesn’t mean the risk is smaller. Timestamps 00:00 – React2Shell Introduction and Log4j Comparison 00:28 – What Is React and How Vibe Coding Introduces Security Risks 02:48 – How the React2Shell Vulnerability Enables Remote Code Execution 05:49 – How Attackers Exploit React2Shell with a Single POST Request 07:28 – Impact of React2Shell RCE on Server Privileges and Access 08:18 – How to Mitigate React2Shell and the Next.js Vulnerability 11:18 – Incident Response for React2Shell Exploitation 13:25 – Ongoing React2Shell…","meta_description":"Log4j caught everyone off guard. React2Shell might be doing the same right now. Across thousands of React apps, exposure is already baked in - accelerated…","key_points":[],"chapters":[],"topics":[],"duration_seconds":888,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/threat-talks-your-gateway-to-cybersecurity-insights-6755159/episodes/react2shell-explained/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/react2shell-explained.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}